{"id":"CVE-2026-52686","summary":"Wildcard CNAME proof validation bypass","details":"The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.","modified":"2026-07-28T04:02:55.944973787Z","published":"2026-07-23T08:03:37.563Z","database_specific":{"cna_assigner":"OX","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52686.json"},"references":[{"type":"WEB","url":"https://repo.powerdns.com/"},{"type":"ADVISORY","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-10.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52686.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52686"},{"type":"PACKAGE","url":"https://github.com/PowerDNS/pdns"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"544037cd123e8662877b5dc0b7963f5a094a2faf"},{"fixed":"b74225ba558d1f9f91afea21e2496e959b13a869"},{"introduced":"ff33413345dc6a826ff0f37f0c78cd60cdf15689"},{"fixed":"53dfd1af948d1ff716bfd7615c99d442f984f2af"},{"introduced":"c95adbda8ce519923dfdbe7947d82a2692e18af9"},{"fixed":"64c4f00f2b3d4d4153837e0dac7979108bb7749d"}],"database_specific":{"extracted_events":[{"introduced":"5.2.0"},{"fixed":"5.2.12"},{"introduced":"5.3.0"},{"fixed":"5.3.9"},{"introduced":"5.4.0"},{"fixed":"5.4.4"}],"source":"AFFECTED_FIELD"}}],"versions":["rec-5.2.10","rec-5.3.7","rec-5.4.2","rec-5.4.0-rc1","rec-5.4.0","rec-5.2.8","rec-5.3.4","rec-5.3.1","rec-5.2.6","rec-5.2.5","rec-5.3.0","rec-5.2.4","rec-5.2.2","rec-5.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52686.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}